DHConnectWIFI is a Windows console helper for connecting to Wi-Fi networks by using the Native Wifi API.
It supports common Wi-Fi workflows such as scanning available networks, connecting with a generated profile, reconnecting with a stored Windows profile, deleting a profile, handling hidden SSID scenarios, and working with both PEAP/MSCHAPv2 and EAP-TLS enterprise authentication.
- Scan nearby Wi-Fi networks
- Show optional BSSID information
- Connect to open networks
- Connect to personal networks such as WPA-PSK and WPA2-Personal
- Connect to 802.1X enterprise networks by using PEAP/MSCHAPv2
- Connect to 802.1X enterprise networks by using EAP-TLS
- Select a specific EAP-TLS client certificate by SHA-1 thumbprint
- Reconnect by using an existing Windows WLAN profile
- Delete an existing Windows WLAN profile
- Handle hidden SSID connections with direct options or console fallback selection
DHConnectWIFI menu
DHConnectWIFI list-iface
DHConnectWIFI scan
DHConnectWIFI scan [--ssid <name>] [--show-bssid true|false]
DHConnectWIFI delete-profile --ssid <name>
DHConnectWIFI connect-profile --ssid <name>
DHConnectWIFI connect --ssid <name> [--username <id>] [--password <pw>] [--domain <name>]
[--eap-method peap|tls] [--server-names <fqdn;fqdn>] [--trusted-root-ca <sha1hex>] [--no-prompt true|false]
[--client-cert-thumbprint <sha1hex>]
[--hidden true|false] [--auth <mode>] [--cipher <mode>]
Environment used for this project:
- Visual Studio 2022
- Windows 10 or later
- C++14 or lower policy in this workspace
Example build command:
"C:\Program Files\Microsoft Visual Studio\2022\Professional\MSBuild\Current\Bin\MSBuild.exe" .\DHConnectWifi\DHConnectWIFI.sln /p:Configuration=Release /p:Platform=x64Build output location:
output\x64\Release\DHConnectWIFI.exe
Version:
1.0.0.2
Scan networks:
DHConnectWIFI.exe scanScan a specific SSID:
DHConnectWIFI.exe scan --ssid homwwifiConnect to a personal network:
DHConnectWIFI.exe connect --ssid homewifi --password mywifipasswordConnect to an enterprise network with PEAP/MSCHAPv2:
DHConnectWIFI.exe connect --ssid homwwifi --eap-method peap --username testuser --password testpassword --domain ""Connect to an enterprise network with PEAP/MSCHAPv2 and trusted Root CA:
DHConnectWIFI.exe connect --ssid homwwifi --eap-method peap --username testuser --password testpassword --domain "" --trusted-root-ca 727A30D0E344AA7C41141791107BD290C64B3C6D --no-prompt trueConnect to an enterprise network with EAP-TLS:
DHConnectWIFI.exe connect --ssid homwwifi --eap-method tls --auth wpa2-enterprise --cipher aes --trusted-root-ca 727A30D0E344AA7C41141791107BD290C64B3C6D --no-prompt trueConnect to an enterprise network with EAP-TLS and a specific client certificate:
DHConnectWIFI.exe connect --ssid homwwifi --eap-method tls --auth wpa2-enterprise --cipher aes --client-cert-thumbprint 76D216AAD8D8D93B4C7F6F17DFFB12DFBA703524 --trusted-root-ca 727A30D0E344AA7C41141791107BD290C64B3C6D --no-prompt trueReconnect by using a stored Windows profile:
DHConnectWIFI.exe connect-profile --ssid homwwifiDelete a stored Windows profile:
DHConnectWIFI.exe delete-profile --ssid homwwifiConnect to a hidden SSID:
DHConnectWIFI.exe connect --ssid hiddenwifi --hidden trueConnect to a hidden SSID with explicit security settings:
DHConnectWIFI.exe connect --ssid hiddenwifi --hidden true --auth wpa2-personal --cipher aes --password secret123- 802.1X enterprise Wi-Fi with PEAP/MSCHAPv2 is supported in the current implementation.
- 802.1X enterprise Wi-Fi with EAP-TLS is supported in the current implementation.
- 802.1X enterprise connectivity was validated against a real FreeRADIUS test environment on CentOS.
- PEAP/MSCHAPv2 authentication was verified with FreeRADIUS running in debug mode by using
radius -X. - EAP-TLS authentication was also verified with a client certificate installed in the Windows certificate store.
- A specific EAP-TLS client certificate can be requested by
--client-cert-thumbprint. - If
--no-prompt falseis used, Windows may wait for certificate confirmation in the Wi-Fi panel. - If
--no-prompt trueis used, certificate trust or server name mismatch can cause silent authentication failure. - For stable enterprise connection, configure the correct trusted Root CA thumbprint and expected server names when required.
- For EAP-TLS, the client certificate must exist in the Windows certificate store and include a private key.
Hidden SSID Notes
- If the hidden SSID can be detected during scan, the tool can reuse the detected security information.
- If the hidden SSID cannot be fully identified, the tool can fall back to console security selection.
- You can still provide
--authand--cipherdirectly if you already know the security mode.
- WPA3-SAE is not currently validated in the available Windows OS and driver environment.
- OWE is not currently validated in the available Windows OS and driver environment.
- Hidden SSID interactive flow currently falls back on security-type selection only. Password, username, and domain are still passed by arguments.
- Detailed usage guide: docs/USAGE.md
- Enterprise guide: docs/ENTERPRISE.md
- Troubleshooting guide: docs/TROUBLESHOOTING.md
MIT License. See LICENSE.